Malware

How to remove “Doina.40994”?

Malware Removal

The Doina.40994 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.40994 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses XCOPY for copying files

How to determine Doina.40994?


File Info:

name: 7BB8CFAE381B4E916485.mlw
path: /opt/CAPEv2/storage/binaries/f04c0463238f0aa0ed5da030e4b38277355afaf3e85512044d9face7d335e5f6
crc32: C3B25CD2
md5: 7bb8cfae381b4e9164854d1330e8c3fa
sha1: 2620e6224b92ab6d7408c8835b2d11ec6ebfe14b
sha256: f04c0463238f0aa0ed5da030e4b38277355afaf3e85512044d9face7d335e5f6
sha512: 844d9827b1c7a77edc43e6312696eb651cca493028a332973baebc69721ddf954b8b179ff1f267b8fc9a3a4e4861f913fd58c329fa169e9d6a09331e2f03638a
ssdeep: 3072:qbKw0nrR2PR0wbR5zL9bZy2WY3YYS8O6Tcc5kzwx/oS4Oqzfa8K0+5VI0cJnhadH:qgk9bRB5bZy2pY6NcEkW74OsfSId0N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DC548D113690C432C516363A499AD7756ABBBE305F3552C77BD03B7DAF322C29A3834A
sha3_384: f55dd01f140b941ae47742651a7e258b67fc306df4e448b0f29f6b560588c70920c69c03c472d6b580fd7813825780f3
ep_bytes: e8b6b40000e978feffff6a0c68984a43
timestamp: 2011-10-03 11:16:48

Version Info:

0: [No Data]

Doina.40994 also known as:

DrWebTrojan.DownLoader5.6247
MicroWorld-eScanGen:Variant.Doina.40994
FireEyeGen:Variant.Doina.40994
ALYacGen:Variant.Doina.40994
CylanceUnsafe
VIPREGen:Variant.Doina.40994
SangforSpyware.Win32.Agent.V0kb
K7AntiVirusSpyware ( 002645061 )
AlibabaTrojanSpy:Win32/Generic.0be085b7
K7GWSpyware ( 002645061 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Agent.NXI
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Agent.bvde
BitDefenderGen:Variant.Doina.40994
NANO-AntivirusTrojan.Win32.Agent.ecqvhl
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.1201b26b
Ad-AwareGen:Variant.Doina.40994
ZillyaTrojan.Agent.Win32.241334
TrendMicroTROJ_GEN.R002C0PI822
McAfee-GW-EditionRDN/Generic PWS.y
EmsisoftGen:Variant.Doina.40994 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Doina.40994
JiangminTrojanSpy.Agent.wyo
GoogleDetected
AviraTR/Spy.Agent.agk.1
Antiy-AVLTrojan/Generic.ASMalwS.3E
ViRobotBackdoor.Win32.Agent.284160.A
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Agent.C124986
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=84)
VBA32TrojanSpy.Agent
MalwarebytesMalware.AI.3361792801
TrendMicro-HouseCallTROJ_GEN.R002C0PI822
RisingSpyware.Agent!8.C6 (TFE:5:UrXS7D7zIgH)
YandexTrojanSpy.Agent!ga2pywrQFi0
IkarusTrojan-Spy.Win32.Agent
MaxSecureTrojan.Malware.3208091.susgen
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Doina.40994?

Doina.40994 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment